Advanced Scrollbar – Custom Scrollbar Styling and Behavior Security & Risk Analysis

wordpress.org/plugins/advanced-scrollbar

Advanced Scrollbar lets you add a scrollbar with customizable color, width, background, and speed for a sleek, branded user experience.

700 active installs v1.1.10 PHP 7.1+ WP 6.5+ Updated Apr 11, 2026
color-scrollbarcursor-effectcustom-scrollnice-scrollbarscrollbar
98
A · Safe
CVEs total1
Unpatched0
Last CVEOct 11, 2025
Download
Safety Verdict

Is Advanced Scrollbar – Custom Scrollbar Styling and Behavior Safe to Use in 2026?

Generally Safe

Score 98/100

Advanced Scrollbar – Custom Scrollbar Styling and Behavior has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 11, 2025Updated 1mo ago
Risk Assessment

The "advanced-scrollbar" plugin v1.1.10 demonstrates several good security practices, including 100% of SQL queries using prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests is also positive. However, a significant concern is the presence of one unprotected AJAX handler out of a total of nine entry points. While the taint analysis shows no critical or high severity flows, and there are no currently unpatched CVEs, the vulnerability history does indicate one past high-severity vulnerability related to Improper Privilege Management. The presence of Freemius v1.0 as a bundled library is also noted, and its version should be monitored for known vulnerabilities.

Key Concerns

  • AJAX handler without authentication check
  • Bundled library (Freemius v1.0) may be outdated
  • Past high severity vulnerability history
Vulnerabilities
1 published

Advanced Scrollbar – Custom Scrollbar Styling and Behavior Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-49900high · 8.8Improper Privilege Management

Advanced scrollbar <= 1.1.8 - Authenticated (Subscriber+) Privilege Escalation

Oct 11, 2025 Patched in 1.1.9 (19d)
Version History

Advanced Scrollbar – Custom Scrollbar Styling and Behavior Release Timeline

v1.1.10Current
v1.1.9
v1.1.81 CVE
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Advanced Scrollbar – Custom Scrollbar Styling and Behavior Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
15 escaped
Nonce Checks
6
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped15 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
csb_adv_scrollbar_cursor_data_settings (inc\cursor.php:36)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Advanced Scrollbar – Custom Scrollbar Styling and Behavior Attack Surface

Entry Points9
Unprotected1

AJAX Handlers 9

authwp_ajax_csb_adv_scrollbar_get_popular_pluginsinc\admin.php:9
authwp_ajax_adv_scrollbar_get_active_pluginsinc\admin.php:10
authwp_ajax_adv_scrollbar_activated_plugininc\admin.php:12
authwp_ajax_csbAdvScrollbarPremiumCheckerinc\cursor.php:9
noprivwp_ajax_csbAdvScrollbarPremiumCheckerinc\cursor.php:10
authwp_ajax_csb_adv_scrollbar_cursor_data_settingsinc\cursor.php:11
authwp_ajax_csb_get_adv_scrollbar_cursor_data_settingsinc\cursor.php:12
noprivwp_ajax_csb_get_adv_scrollbar_cursor_data_settingsinc\cursor.php:13
authwp_ajax_csbScrollbarOptionsinc\Settings.php:5
WordPress Hooks 11
actionwp_enqueue_scriptsadvanced-scrollbar.php:64
actionwp_footeradvanced-scrollbar.php:65
actionadmin_enqueue_scriptsinc\admin.php:6
actionadmin_menuinc\admin.php:7
actionadmin_noticesinc\admin.php:11
actioninitinc\cursor.php:5
actionthe_contentinc\cursor.php:6
actionenqueue_block_assetsinc\cursor.php:7
actionenqueue_block_editor_assetsinc\cursor.php:8
actioninitinc\import.php:10
actionadmin_enqueue_scriptsinc\Settings.php:6
Maintenance & Trust

Advanced Scrollbar – Custom Scrollbar Styling and Behavior Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 11, 2026
PHP min version7.1
Downloads37K

Community Trust

Rating60/100
Number of ratings7
Active installs700
Developer Profile

Advanced Scrollbar – Custom Scrollbar Styling and Behavior Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Scrollbar – Custom Scrollbar Styling and Behavior

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-scrollbar/assets/js/jquery.nicescroll.min.js/wp-content/plugins/advanced-scrollbar/build/scrollbar.css/wp-content/plugins/advanced-scrollbar/build/scrollbar.js
Script Paths
/wp-content/plugins/advanced-scrollbar/assets/js/jquery.nicescroll.min.js/wp-content/plugins/advanced-scrollbar/build/scrollbar.js
Version Parameters
advanced-scrollbar/assets/js/jquery.nicescroll.min.js?ver=advanced-scrollbar/build/scrollbar.css?ver=advanced-scrollbar/build/scrollbar.js?ver=

HTML / DOM Fingerprints

CSS Classes
advScrollbar-notice
Data Attributes
data-scrollbar
JS Globals
CSB_VERSIONCSB_DIR_URLCSB_DIR_PATHCSB_HAS_FREECSB_HAS_PROasb_fs
REST Endpoints
/wp-json/advanced-scrollbar/v1/plugins/wp-json/advanced-scrollbar/v1/active-plugins
Shortcode Output
<div id="csbScrollbar"
FAQ

Frequently Asked Questions about Advanced Scrollbar – Custom Scrollbar Styling and Behavior